First published: Mon Jun 04 2018(Updated: )
IBM Security Access Manager Appliance 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 stores potentially sensitive information in log files that could be read by a remote user. IBM X-Force ID: 128617.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager | >=9.0.0<=9.0.3.1 | |
IBM Security Access Manager for Web | >=8.0.0<=8.0.1.6 | |
IBM Security Access Manager for Mobile | >=8.0.0<=8.0.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2017-1480.
The severity of CVE-2017-1480 is medium (4.3).
IBM Security Access Manager Appliance versions 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 are affected.
CVE-2017-1480 allows a remote user to read potentially sensitive information stored in log files.
Yes, IBM has provided fixes for the affected versions of IBM Security Access Manager Appliance. Please refer to the IBM support documentation for specific details.